๐Ÿคฒ๐Ÿผ NEW | abuse.ch Community Hub! Earn recognition ๐Ÿ… for the malware intelligence you share, climb the leaderboards ๐Ÿ“ˆ, and connect with like-minded contributors who share your hunting focus ๐Ÿค. Ready to unlock your profile? Go to the Community Hub โ†’

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d4ed775d9ac6ed01f2563c43a41788322a5b7d8a32b14380e3516dfc7808da2f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



GuLoader


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: d4ed775d9ac6ed01f2563c43a41788322a5b7d8a32b14380e3516dfc7808da2f
SHA3-384 hash: 9bd2b690d4dc80fc2ffbe1088f572a8b54cfa2b63b8727ce8518fed2c980ca4a50ace5372ea3575505053347ecc41cc7
SHA1 hash: aace7b732b7abedce1e0e257ab2dfa75db9add40
MD5 hash: bd4449c307946880ebfb2744a4aa5052
humanhash: oklahoma-spring-single-oranges
File name:N.ยบ de pedido - RBLTIERR013.pdf.bat
Download: download sample
Signature GuLoader
File size:5'507 bytes
First seen:2026-08-19 06:05:34 UTC
Last seen:Never
File type:Batch (bat) bat
MIME type:text/plain
ssdeep 96:ew18u/nrXjrVNUvlFcU5f4Qy2h3lyZMwEEc1EAmp2R3am5eY+yXjQfzK:1qufrXjrVNUtFcYgQy2Dk41EAmp2R3aC
TLSH T138B1B8383308F58851869795007EECC26C76573D9AE2AE14B6EDDA4EE963C4C5B3C4DC
Magika powershell
Reporter lowmal3
Tags:bat GuLoader

Intelligence


File Origin
# of uploads :
1
# of downloads :
128
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Malware family:
n/a
ID:
1
File name:
bat
Verdict:
No threats detected
Analysis date:
2026-08-19 06:17:36 UTC
Tags:
n/a

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Suspicious
Maliciousness:

Behaviour
Launching a process
DNS request
Connection attempt
Sending a custom TCP request
Creating a file in the %AppData% directory
Using the Windows Management Instrumentation requests
Creating a process with a hidden window
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
base64 crypto encrypted masquerade obfuscated powershell
Result
Threat name:
GuLoader
Detection:
malicious
Classification:
troj.evad
Score:
88 / 100
Signature
Found suspicious powershell code related to unpacking or dynamic code loading
Joe Sandbox ML detected suspicious sample
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sigma detected: Potential PowerShell Command Line Obfuscation
Suspicious powershell command line found
Switches to a custom stack to bypass stack traces
Writes to foreign memory regions
Yara detected GuLoader
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1960185 Sample: N.#U00ba de pedido - RBLTIE... Startdate: 19/08/2026 Architecture: WINDOWS Score: 88 29 drive.usercontent.google.com 2->29 31 drive.google.com 2->31 39 Malicious sample detected (through community Yara rule) 2->39 41 Multi AV Scanner detection for submitted file 2->41 43 Yara detected GuLoader 2->43 45 3 other signatures 2->45 7 powershell.exe 15 2->7         started        10 cmd.exe 1 2->10         started        12 svchost.exe 1 1 2->12         started        15 rundll32.exe 2->15         started        signatures3 process4 dnsIp5 47 Writes to foreign memory regions 7->47 49 Found suspicious powershell code related to unpacking or dynamic code loading 7->49 51 Switches to a custom stack to bypass stack traces 7->51 17 wab.exe 3 1 7->17         started        19 conhost.exe 7->19         started        21 wab.exe 7->21         started        53 Suspicious powershell command line found 10->53 23 powershell.exe 19 10->23         started        27 conhost.exe 10->27         started        37 127.0.0.1 unknown unknown 12->37 signatures6 process7 dnsIp8 33 drive.usercontent.google.com 192.178.155.132, 443, 49701 GOOGLE-GoogleLLCUS United States 23->33 35 drive.google.com 192.178.155.139, 443, 49700 GOOGLE-GoogleLLCUS United States 23->35 55 Found suspicious powershell code related to unpacking or dynamic code loading 23->55 signatures9
Threat name:
Script-PowerShell.Trojan.GuLoader
Status:
Malicious
First seen:
2026-08-19 01:44:54 UTC
File Type:
Text
AV detection:
11 of 24 (45.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
defense_evasion discovery execution
Behaviour
Modifies registry class
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Executes a command shell one-liner
System Location Discovery: System Language Discovery
Suspicious use of NtSetInformationThreadHideFromDebugger
Command and Scripting Interpreter: PowerShell
Contacts third-party web service commonly abused for C2
Obfuscated Files or Information: Command Obfuscation
Badlisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments